West Coast Management and Realty Data Breach

Alleged

Ransomware claim involving West Coast Management and Realty

Published: Aug 19, 2026 Settra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
West Coast Management and Realty
Industry
Business Services
Threat Actor
Settra
Date of Incident
Aug 19, 2026

Executive Summary

Settra ransomware group listed West Coast Management and Realty on its dark web portal on August 19, 2026, as identified through SOCRadar’s Dark Web Monitoring. As a company operating in the real estate and property management sector, West Coast Management and Realty is a potential target due to the sensitive data it likely holds, including tenant personally identifiable information (PII), lease and financial records, and operational documentation. This type of data can be used for extortion, leveraging direct influence over current tenants. The specific country of operation for West Coast Management and Realty was not specified in the listing. The August 19th batch of claims by Settra also included M.A.K. Freight Systems in Malaysia (Transportation), Greco Steel Products in Greece (Manufacturing), AMBITION Group in Japan, and ALPHANUMERIC SYSTEMS, INC. in the US. Settra has demonstrated a broad targeting strategy, not adhering to a specific industry vertical, with previous victims identified in transportation, manufacturing, business services, and technology sectors, now including real estate. This diverse targeting suggests the group is opportunistic and may exploit vulnerabilities across various industries.

Technical Analysis

Stealer-log correlation for West Coast Management and Realty returned three employee credential records. These records were associated with Microsoft Entra ID (login.microsoftonline.com) and Microsoft Live authentication (login.live.com), with a freshness window extending from June 2024 to March 2026. This indicates that some credentials may have been unrotated for up to two years. Such long-aged Microsoft identity credentials, if still valid, represent a valuable commodity for initial access brokers. Organizations that have not rotated their credentials since 2024 are also less likely to have robust security measures like Conditional Access policies or Multi-Factor Authentication (MFA) enforced. The findings suggest a potential attack vector through compromised Microsoft credentials. It is recommended that West Coast Management and Realty rotate these identified Entra credentials immediately. Furthermore, an audit of sign-ins against both Microsoft Entra ID and login.live.com endpoints is crucial for identifying anomalous sessions that may have occurred between June 2024 and August 2026. Continued monitoring of dark web and stealer-log feeds is also advised to detect any further credential exposures or new claims by Settra.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.